The eCommerce Product Catalog plugin for WordPress has a security issue in versions up to 3.0.69. Attackers can inject malicious web scripts into pages if they can convince someone to click on a link. This is possible because the plugin does not properly sanitize or escape certain user inputs.